Django:如何限制仅管理员验证用户发博客并在模板检查字段
Got it, let's break down how to implement this requirement step by step. You want to restrict blog posting access to only users verified by site admins, checking the is_verifieduser field from your UserProfileInfo model during template rendering. Here's what you need to do:
First, ensure your view sends the logged-in user's UserProfileInfo instance to the template. This works for both function-based and class-based views:
For Class-Based Views
from django.views.generic import TemplateView from .models import UserProfileInfo class BlogCreateView(TemplateView): template_name = "blog/create_post.html" def get_context_data(self, **kwargs): context = super().get_context_data(**kwargs) # Fetch the user's profile if they're logged in if self.request.user.is_authenticated: context["user_profile"] = UserProfileInfo.objects.get(user=self.request.user) return context
For Function-Based Views
from django.shortcuts import render from .models import UserProfileInfo def create_blog_post(request): context = {} if request.user.is_authenticated: context["user_profile"] = UserProfileInfo.objects.get(user=request.user) return render(request, "blog/create_post.html", context)
Now in your template, use Django's template logic to check the is_verifieduser flag and show/hide the blog posting form accordingly:
{% if user.is_authenticated %} {% if user_profile.is_verifieduser %} <!-- Show the blog post submission form here --> <form method="POST" action="{% url 'blog:submit_post' %}"> {% csrf_token %} <div> <label for="title">Blog Title:</label> <input type="text" id="title" name="title" required> </div> <div> <label for="content">Content:</label> <textarea id="content" name="content" rows="8" required></textarea> </div> <button type="submit">Publish Blog</button> </form> {% else %} <p>Sorry, only verified users can publish blogs. Reach out to the site admin to get your account verified.</p> {% endif %} {% else %} <p>Please log in first to create a blog post.</p> {% endif %}
Template checks are great for UI, but they don't stop users from submitting posts directly (e.g., via curl or modified frontend code). Always add server-side validation in your submission view:
from django.http import HttpResponseForbidden from django.shortcuts import redirect, render from .forms import BlogPostForm from .models import UserProfileInfo def submit_blog_post(request): # Check if user is logged in if not request.user.is_authenticated: return HttpResponseForbidden("You need to log in to post a blog.") # Fetch user profile (handle case where profile doesn't exist) try: user_profile = UserProfileInfo.objects.get(user=request.user) except UserProfileInfo.DoesNotExist: return HttpResponseForbidden("Your user profile could not be found.") # Block non-verified users if not user_profile.is_verifieduser: return HttpResponseForbidden("Only verified users are allowed to publish blogs.") # Handle form submission if request.method == "POST": form = BlogPostForm(request.POST) if form.is_valid(): blog_post = form.save(commit=False) blog_post.author = request.user blog_post.save() return redirect("blog:post_detail", pk=blog_post.pk) else: form = BlogPostForm() return render(request, "blog/create_post.html", {"form": form, "user_profile": user_profile})
内容的提问来源于stack exchange,提问作者KaNishk SiNghal

